SubProcessor List

05_Subprocessor_List


AMII Platform — Subprocessor List

Vendors that may process personal information on behalf of AMII

DRAFT FOR PROCUREMENT AND LEGAL REVIEW

Effective date: July 23, 2026. Only publish vendors that are actually contracted, enabled, and receiving AMII data. Replace all bracketed fields.

1. Scope

This list identifies service providers that may process personal information for [AMII LEGAL ENTITY NAME] in connection with AMII Platform. A vendor should be listed only after AMII verifies the service, data categories, processing location, security terms, data-processing agreement, and production configuration.

2. Confirmed or Expected Core Providers

Microsoft Corporation — Identity and Authentication

Service: Microsoft Entra ID, Microsoft Identity, and related authentication services.

Purpose: account sign-in, single sign-on, organizational identity, authentication, authorization support, and security.

Data: name, email, account identifier, role-related identity information, authentication events, tokens, IP address, and device/browser information.

Status: Active for Microsoft sign-in. Confirm the applicable Microsoft contracting entity, region, and data-processing terms.

[PRODUCTION HOSTING PROVIDER] — Application Hosting

Purpose: host the AMII web application, APIs, background services, and network infrastructure.

Data: all categories required to operate the hosted service, potentially including account, reservation, health, document, chart, treatment, feedback, audit, and technical data.

Status: Must be completed after the final production host is selected.

[PRODUCTION DATABASE AND FILE-STORAGE PROVIDER]

Purpose: database hosting, backups, uploaded document storage, and disaster recovery.

Data: account, reservation, chart, treatment, insurance, identification, feedback, and audit information.

Status: Confirm whether this is the same vendor as the application host and identify storage regions and backup retention.

Apple Inc. — App Distribution and Platform Services

Service: Apple App Store, App Store Connect, TestFlight, and Apple platform diagnostics or push-notification services if enabled.

Purpose: distribute, test, review, update, and operate the iOS application.

Data: developer-account data, app metadata, test information, device/platform data, diagnostics, push token, and user data only to the extent transmitted through enabled Apple services.

Status: Planned for iOS distribution. Confirm the exact Apple services enabled in the production build.

Google LLC — App Distribution and Platform Services

Service: Google Play, Play Console, Android platform services, Play Integrity, crash reporting, or push-notification services if enabled.

Purpose: distribute, test, review, update, secure, and operate the Android application.

Data: developer-account data, app metadata, test information, device/platform data, diagnostics, integrity information, push token, and user data only to the extent transmitted through enabled Google services.

Status: Planned or active for Android distribution. Confirm whether Firebase, Crashlytics, Analytics, or Firebase Cloud Messaging is actually included.

[EMAIL DELIVERY PROVIDER]

Purpose: account, reservation, treatment, follow-up, security, policy, support, and optional promotional email.

Data: name, email address, message content, delivery status, and related account or workflow identifiers.

Status: Confirm whether Microsoft 365 or another provider sends production email.

[SMS PROVIDER — NOT YET SELECTED]

Purpose: service-related SMS notifications and reminders if enabled.

Data: phone number, message content, delivery status, and limited reservation or workflow information.

Status: Not active until AMII selects and contracts with a provider. Do not list Twilio or another vendor as active merely because it is under consideration.

[MONITORING, ERROR-LOGGING, OR SUPPORT PROVIDER]

Purpose: application monitoring, crash reporting, error analysis, security, customer support, or incident response.

Data: IP address, device/browser information, app version, logs, error details, support content, and limited account identifiers.

Status: Complete only for vendors actually enabled in production.

3. Other Recipients That May Not Be Subprocessors

Dentists and dental practices may receive patient information as independent healthcare providers or separate regulated entities rather than as subprocessors acting solely on AMII’s instructions. Their status, privacy notice, record obligations, and data-sharing relationship should be addressed in provider agreements and user disclosures.

Apple and Google may act as independent platform providers for certain store, device, billing, or analytics data. Their classification depends on the specific service and contract.

4. Vendor Requirements

• Written contract and confidentiality obligations.

• Data-processing and security terms appropriate to the information handled.

• Access limited to authorized purposes.

• Incident-notification obligations.

• Deletion or return of data when services end, subject to lawful retention.

• Subprocessor change and downstream-vendor controls.

• Healthcare or HIPAA-related agreements where legally required.

5. Changes to the List

AMII may update this list when vendors are added, removed, or materially changed. Material changes should be posted before the vendor begins processing sensitive production data when contractually or legally required.

6. Contact

Questions about subprocessors may be sent to [PRIVACY EMAIL].

An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.